PUF-Based Software Integrity Verification Circuit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for verifying the integrity of software in electronic devices are vulnerable to attacks, particularly due to the use of cryptographic keys which can compromise security and increase energy consumption and calculation time.
Innovation Solution
A process and circuit utilizing a physically unclonable function (PUF) to generate and compare verification values, ensuring the integrity of software by outputting a warning signal if differences are detected, with the PUF being specific to each device and implemented to generate reference values based on software and random values, enhancing security without relying on shared encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are used to encrypt reference values for verification, then security is improved, but energy consumption and calculation time increase
Solution Approach 1:
The patent extracts the cryptographic key dependency from the verification process by using PUF-generated reference values that are inherently tied to the device's physical characteristics. This eliminates the need for separate key management and encryption operations, reducing energy consumption while maintaining security.
Solution Approach 2:
The PUF circuit generates reference values autonomously based on the device's own physical characteristics without requiring external cryptographic keys. The verification process becomes self-contained, using the device's inherent physical properties for both generation and verification of reference values.
2Reliability
If cryptographic keys are used to encrypt reference values for verification, then security is improved, but calculation time increases
Solution Approach 1:
The patent removes the time-consuming cryptographic encryption and decryption operations from the verification process. By using PUF-based reference values that are naturally bound to the device, the system eliminates the need for key-based encryption while maintaining equivalent or superior security.
Solution Approach 2:
The reference values are generated in advance during device manufacturing using the PUF circuit's physical characteristics. This preliminary generation eliminates the need for real-time cryptographic operations during verification, significantly reducing calculation time while maintaining security.
3Reliability
If standard verification methods are used, then verification capability is provided, but devices are vulnerable to attacks and code modification
Solution Approach 1:
The patent makes each device's verification reference values locally unique by tying them to the device's specific physical characteristics through the PUF circuit. This local differentiation ensures that reference values cannot be transferred or replicated between devices, preventing code injection and modification attacks.
Solution Approach 2:
The PUF circuit acts as an intermediary that translates the device's physical characteristics into unique reference values. This intermediary layer provides an additional security barrier that prevents direct attacks on the verification process, as the PUF's physical unclonability protects against reverse engineering and manipulation.
Data Source
AI summary
The present disclosure relates to a process for verifying the integrity of software by a verification circuit, the process comprising: loading (401) the software into a first volatile memory; computing (402) a first verification value by the verification circuit; computing (403) a second verification value by applying a physically unclonable function to the first verification value; comparing (404), by the verification circuit, the second verification value with a reference value; and if it is found that the second verification value differs from the reference value, generating a warning signal (405) at the output of the verification circuit.


